GDPR Compliance

GDPR Compliance

SendBaba is fully committed to GDPR compliance. Learn how we protect EU citizens' data and uphold their privacy rights.

Last Updated: January 4, 2026

What is GDPR?

The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into effect on May 25, 2018. It governs how organizations collect, store, and process personal data of individuals in the European Union.

Key Principle: GDPR gives individuals control over their personal data and requires organizations to be transparent about how they use it.

Our GDPR Commitment

SendBaba is committed to GDPR compliance and has implemented comprehensive measures to protect your data:

Data Processing Agreement

We provide DPAs to all customers processing EU data

Privacy by Design

Data protection built into our systems from the ground up

Data Minimization

We only collect data necessary for our services

Transparent Processing

Clear documentation of how we process your data

Your Rights Under GDPR

As an EU resident, you have the following rights regarding your personal data:

Right to Access

You can request a copy of all personal data we hold about you. We will provide this within 30 days.

Right to Rectification

You can request that we correct any inaccurate or incomplete personal data we hold about you.

Right to Erasure (Right to be Forgotten)

You can request that we delete your personal data when it's no longer necessary for the purpose it was collected.

Right to Data Portability

You can request your data in a machine-readable format to transfer to another service provider.

Right to Object

You can object to certain types of processing, including direct marketing and profiling.

Right to Restrict Processing

You can request that we limit how we use your data in certain circumstances.

How We Process Data

Role Description
Data Controller You (our customer) are the data controller for your subscribers' data
Data Processor SendBaba acts as a data processor, processing data on your behalf
Sub-processors We use vetted sub-processors who are also GDPR compliant

International Data Transfers

When transferring data outside the EU/EEA, we ensure appropriate safeguards:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data Processing Agreements with all sub-processors
  • Technical and organizational measures to protect data in transit
  • Regular assessments of transfer mechanisms

GDPR Features in SendBaba

We provide tools to help you comply with GDPR:

Double Opt-in

Confirm subscriber consent

Data Export

Export data anytime

Easy Deletion

Delete contacts instantly

Consent Tracking

Track opt-in timestamps

Unsubscribe Links

Automatic in every email

Audit Logs

Track all data changes

Data Protection Officer

For GDPR-related inquiries or to exercise your rights, contact our DPO.

dpo@sendbaba.com